Start with the conclusion: the face in a video call is no longer proof of identity. You can see them, hear them, and watch them answer your questions on the spot — three things that used to add up to "confirmed, it's him," and now add up to "someone was willing to spend a little compute." One verification step still works: hang up, and call back on a channel you saved yourself. This piece covers what deepfakes actually look like in crypto, why "ask him to wave his hand" has stopped working, and how to turn that one rule into something you can act on.
- A video call is not identity. All it proves is that someone is playing you a picture.
- Waving a hand, pressing the nose, turning the head — those tricks can only disqualify, never confirm. A glitch means fake; no glitch means nothing at all.
- The one thing that holds: hang up, then call back on a number you already had, or through a channel inside the official app. Never on a contact detail they supplied.
Where deepfakes actually show up in crypto
Most public warnings about deepfakes reach for the same two examples: a relative asking for money on video, and a bank manager. Both are real. But crypto has its own set of scenes, and the sums tend to be larger. Here are four you can genuinely run into.
1 · The "chief analyst" in a livestream
An investment livestream that looks entirely above board: an office backdrop, candlestick charts on the screen behind, a "chief analyst" talking fluently, a chat full of people saying they got in and are up. That face may be an AI swap. A Xinhua report from November 2025 took one of these apart — the "chief analyst" was an AI-generated persona, and the real person was someone else. The closing move never varies: you get pulled out of the livestream into a private group, told to install an "exclusive app," then told to move your money into a "safe account."
2 · "Let's hop on video" in an OTC trade
For a large over-the-counter swap, both sides often open a video call to "make sure there's a real person on the other end." That habit is now the hole. The other side can pair an ID photo with a synthetic video, let you verify with your own eyes, and take your coins or your cash first. Verifying on video isn't the mistake. Treating it as a guarantee is.
3 · The executive-impersonation group call
The best-known public case is from Hong Kong in 2024. According to Hong Kong media reports, an employee of a multinational engineering firm was invited to a video meeting with "head-office executives"; everyone on the call except him was a deepfake, and he sent the money out in more than a dozen separate transfers, with the amount put by Hong Kong media at around HK$200 million. It isn't a crypto case, but the structure transfers cleanly: project treasuries, institutional OTC desks and market-maker back offices all run workflows where an executive gives a payment instruction verbally on a call. The damage comes from the crowd — when a room of familiar faces is nodding, hitting pause feels rude.
4 · The "investigator" who arrives after you've been scammed
This one is the ugliest. You were scammed once. A few weeks later someone claiming to be from law enforcement gets in touch, says there's movement on your case and they can recover your funds, and sends over a video of an "official." The FBI's IC3 named this pattern in a public service announcement on 20 July 2026: scammers impersonating IC3 and FBI personnel, using AI-generated video and spoofed websites, going after people who have already been defrauded. Victim lists circulate as a commodity, so the second cut usually comes fast.
Four scenes, four different faces, one core: a face you're willing to trust, standing in for the check you should have run. The face doesn't have to be perfect. It only has to last the few minutes before you hit send.
If the face on your screen is talking about "AI quant, follow the bot, steady returns," you are probably looking at two links in one chain — a synthetic video of a celebrity or "analyst" doing the recruiting at the front, a fund that pays old money with new money at the back. That half is covered separately in "AI Trading Bot," "Risk-Free Arbitrage".
Why "ask him to wave" stopped working
You've probably seen the tip: on a video call, ask the person to wave a hand across their face, press their nose, or turn their head quickly, and the swapped face will smear while the edges jitter. The tip was genuinely useful once, because early face-swap models did fall apart on occlusion, sharp profile angles and fast movement.
The trouble is that it has become a published exam question. The wider a piece of anti-fraud advice spreads, the harder the toolmakers work against it — occlusion handling, profile reconstruction and lip sync have all been optimisation targets in recent years. The Xinhua report from November 2025 says as much: newer real-time synthesis holds up noticeably better against exactly these small movements. So you ask him to wave, he waves, nothing smears — and you have proved nothing.
Demote it to a veto
These moves aren't useless; they only run in one direction. The moment you see soft edges, mangled ears or hair, lips out of sync, or the picture tearing where a hand crosses the face, call it fake and stop deliberating. The reverse does not follow: seeing no flaw does not make the person real. Fine as a filter, dangerous as a verdict.
There's a less obvious problem underneath. Plenty of victims didn't "miss the flaw" — they were never looking at the face. You're tense, doing arithmetic, being hurried; your attention is entirely on whether to send the money, and a small visual oddity never reaches conscious thought. That's why the rule in the next section doesn't lean on your eyesight. It moves the decision from "can I spot it" to "will I follow the procedure." On how attention gets hijacked in the first place, Why "I'd never fall for it" is the most dangerous thought goes further.
The move that still works: hang up, call back another way
If you keep one thing from this page, keep this: the moment the person on video starts asking for money, for a code, or for you to install something, hang up — then call back on a completely separate channel to verify.
Why does that hold when studying the face doesn't? A deepfake forges content — face, voice, tone, background. What it cannot forge is a route he doesn't control. Put yourself at the initiating end and the setup he built collapses.
- Take the number out of your own contacts, not out of the call log. Caller ID can be spoofed, and a messenger account can be a freshly registered look-alike. Use the entry you saved earlier.
- For anything platform-related, go in through the app or the official site. Not a link they sent you, not a support number from search results. Same principle as Fake support & "account frozen / unfreeze" scams, except this time the scammer also has a face.
- Switch medium; don't "double-check" inside the same app. If he can impersonate someone on a messenger, he can catch your verification message on that same messenger. He started it on video, so call him on the phone; the account is on Telegram, so dial his real number.
- Ask about something small that only the real person knows and that has never been online. Not "what's your name" but "what was that place we ate at last time called." Avoid anything sitting on their public profiles. This is a support move; the callback is the main one.
- Inside a company, write two-person approval into the rules. Any payment instruction given verbally on a call gets a second confirmation offline or over another route. Don't leave it to judgment in the moment — with a room of "colleagues" watching, people find it very hard to say stop.
The one-line version
Verification has to travel outward from you, not inward from him. Whatever arrives on his initiative is a video, however convincing it looks; only what you dial on your own saved route counts as verification. The two minutes in between are the best-value two minutes in this whole category of scam.
Red flags you can catch without looking at the face
Here's the good news. The face swap only changes whether you believe the person. It doesn't change what the second half of the scam has to make you do — and those steps are easy to recognise.
| What you see or hear | What it means | What to do |
|---|---|---|
| A transfer, a payment on someone's behalf, or a coin loan asked for during the call | A payment instruction is itself the strongest signal, whoever is asking | Hang up; call back on another channel to confirm |
| You're told to install an "exclusive" or "internal" app | No legitimate financial institution asks you to install anything from outside the app stores | End the call; install only from the official app stores |
| You're asked to share your screen so they can "walk you through it" | What they want is a look at your codes and your account pages | Refuse, whatever reason is offered |
| You're told to move funds into a "safe account" or a "dedicated account" | No such thing exists in a legitimate process | Call it fraud and hang up |
| Someone claims to be law enforcement and offers to recover your stolen funds | The standard second-wave script | Don't engage; check the case yourself through official channels |
| You're pushed the whole way through — "do it now," "the meeting is waiting" | Time pressure, applied precisely so you don't verify | The harder they push, the more you stop; hang up first |
Set that table next to the one rule and something reassuring falls out: you don't need to be able to detect a deepfake at all. You only need to hold the hang-up-and-call-back line whenever one of those requests appears. However much compute went into that face, it can't get around those two steps.
What the AI-labelling rule does and doesn't do for you
China's Measures for Labelling AI-Generated Synthetic Content took effect on 1 September 2025, issued jointly by the Cyberspace Administration and three other departments. Two core requirements: providers must attach an explicit label to generated content (visible text or a corner marker), and an implicit label in the file metadata (content attributes, provider information and the like).
That's a good development. Its practical value to you, though, has edges worth stating plainly.
- It binds providers who follow rules, not scam operations. The tools scammers use mostly circulate offshore or underground, outside the system to begin with, and they can strip a label that is already there. Expecting a scammer to mark his own video as AI is not realistic.
- So a label reads in one direction only. If you see one, the content is almost certainly synthetic. If you don't see one, nothing follows. It can help you confirm "this is fake"; it can't help you confirm "this is a real person."
- Metadata falls off easily in circulation. Forwarding, compression, screen recording and re-editing can all strip the implicit label. So "I downloaded it and found no label in the metadata" isn't evidence either.
Put differently, the rule raises the floor for the content ecosystem as a whole; it doesn't hand you a personal instrument for telling real from fake. At the moment money is about to move, what saves you is still the rule in the section above.
Already sent the money: one extra thing to keep in a deepfake case
The full sequence — stopping the loss, preserving evidence, reporting — is in I just got scammed. What do I do right now?, so we won't repeat it here. A deepfake case adds exactly one item, and it matters:
Keep the original video file. Don't transcode it, don't settle for a screenshot
If you have video or audio the other side sent you, or a screen recording of the call, keep the original file exactly as it is. Don't forward it to anyone through a messenger (most re-compress it), don't keep only screenshots, don't convert the format to save space. The original may carry encoding traces and metadata with forensic value, and a single round of compression often removes them. Save a copy locally or to cloud storage first, then go do everything else.
One thing to brace for in advance: after a scam, there's a good chance someone approaches you offering to get the money back. That's what the IC3 announcement above is about — and these days the person may arrive with a "law enforcement" face attached. That script has its own page: USDT "recovery / unfreeze" scams.
If you're not sure which category the thing in front of you falls into, or how dangerous it is, put it through the 30-second scam self-check first, or take it through the general framework in Run any "opportunity" through these 7 steps first. To see where this one sits on the whole map, go back to the Crypto Scam Field Guide.
FAQ
Can asking someone to wave a hand or press their nose still expose a face swap on a video call?
It helps, but it can no longer carry the decision on its own. It used to work because early face-swap models broke on occlusion and profile angles. The Xinhua report of November 2025 notes that newer real-time synthesis holds up much better against those small movements — you can ask for them and see nothing at all. So use it demoted: a visible flaw means fake, full stop; no visible flaw does not mean a real person. Only one move settles it — hang up and call back on a number you saved yourself, or through a channel inside the official app.
Can a face swap beat an exchange's facial recognition?
Turn the question around. What you saw on the call — "look, I just passed face verification" — is a picture the other side chose to show you, not a confirmation the platform sent you; the whole "verification successful" sequence can be a screen recording or a synthetic clip. So whether or not it's technically possible, it shouldn't count as evidence that the person is real. The other direction deserves attention too: clear, front-facing video of your own face is sensitive material. Don't hand it to people you don't know, and don't perform requested movements on camera to "help with a verification."
Isn't AI-generated content required to be labelled? If I see no label, does that mean it's a real person?
That doesn't follow. The Measures for Labelling AI-Generated Synthetic Content took effect on 1 September 2025 and require providers to attach an explicit label to generated content and an implicit label in the file metadata. They bind providers who follow rules. Scam operations work with offshore or underground tools that were never going to label anything, and they can strip labels that are already present. So a label reads in the positive direction only: seeing one means the content is almost certainly synthetic; not seeing one proves nothing.
How do I quickly judge whether the "chief analyst" in a livestream is a real person?
Don't start with real or fake — start with what he's asking you to do. Xinhua reported a case in November 2025 where the livestream's "chief analyst" was a face-swapped stand-in, and the next steps were to install an "exclusive app" and move money into a "safe account." Legitimate financial institutions ask for neither. The moment any one of "join the private group," "install this app" or "transfer to this account" shows up, whose face it is stops mattering. Leave.
It's someone I know, and the voice and speech habits all match. Do I still need to verify?
Yes — and this is exactly the case that most needs verifying. Impersonating someone you trust is the whole point of a deepfake; the closer the match, the more work went into it. The line isn't "does it look like him," it's "is he asking for money": as soon as the conversation turns to a transfer, a payment on his behalf, a USDT loan or a verification code, hang up however well you know him, and call the old number in your contacts to ask. Two extra minutes is the cheapest cost in this category of scam.
Sources used in this piece
Everything here that involves a rule, an announcement or a specific case is listed below, so you can check it yourself. This site has run no deepfake detection tests of its own, and no figure in this piece was produced by us.
- FBI Internet Crime Complaint Center, FBI Warns of Scammers Impersonating the IC3 (number I-072026-PSA, 20 July 2026) — impersonating IC3 and FBI personnel, using AI-generated video and spoofed websites, going after people who have already been defrauded.
- Cyberspace Administration of China and three other departments, Measures for Labelling AI-Generated Synthetic Content — in force from 1 September 2025; the specific explicit- and implicit-label requirements are set out in the text of the measures.
- Xinhua, "Is what's in front of you even real? Investment scams behind AI-generated personas," 17 November 2025 (in Chinese) — the livestream "chief analyst" was a face-swapped stand-in; the piece notes that legitimate financial institutions do not ask you to move funds into an "exclusive app" or a "safe account."
- A face-swap case reported by Baotou police in 2023: the victim was defrauded of 4.3 million yuan within ten minutes, and police froze payments in time to recover 3,368,400 yuan (per public reporting from Shanwei police, Beijing Daily and others).
- The 2024 deepfake video-meeting case at a multinational engineering firm in Hong Kong: an employee sent funds out in more than a dozen transfers during a "group meeting," with the amount put by Hong Kong media at around HK$200 million (per reporting from HK01, Economic Daily and others; outlets differ slightly in what they disclose, so only the order of magnitude is taken here).
- A case reported by The Beijing News in May 2026: scammers used a face swap to impersonate a bank relationship manager, combined with screen sharing and a pushed app install; the victim lost more than 200,000 yuan.
- An investigative report by Xinhua News Agency in June 2026: the servers behind the face-swap underground trade are mostly located offshore, and its transactions are largely settled in cryptocurrency.
The amounts in those cases follow the public reporting at the time; outlets may differ, and we have neither re-converted the figures nor used them as trend data.
any trading-fee discount is up to 20%, with the actual rate and eligibility subject to current OKX terms.
Run any "opportunity" through these 7 steps first
Read next
- Fake support & "account frozen / unfreeze" scams — the same "official entry points only" principle, in the version without a face.
- "AI Trading Bot," "Risk-Free Arbitrage" — once the synthetic video has brought someone in, this is usually what's waiting.
- Telegram fake-admin DM scams — the other main arena for impersonation, and lately it comes with video attached.